Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors Fox Kitten

Also known as: UNC757, Parisite, Pioneer Kitten, RUBIDIUM, Lemon Sandstorm

Description

Fox Kitten is threat actor with a suspected nexus to the Iranian government that has been active since at least 2017 against entities in the Middle East, North Africa, Europe, Australia, and North America. Fox Kitten has targeted multiple industrial verticals including oil and gas, technology, government, defense, healthcare, manufacturing, and engineering.(Citation: ClearkSky Fox Kitten February 2020)(Citation: CrowdStrike PIONEER KITTEN August 2020)(Citation: Dragos PARISITE )(Citation: ClearSky Pay2Kitten December 2020)

AI Analysis

· 1 week ago

Executive Summary

Fox Kitten (aka UNC757, Parisite, Pioneer Kitten, RUBIDIUM, Lemon Sandstorm) is a suspected state-sponsored cyber threat group with links to the Iranian government. Active since at least 2017, Fox Kitten has targeted multiple sectors globally, including oil and gas, technology, government, defense, healthcare, manufacturing, and engineering. The group employs advanced persistent threat (APT) tactics, often leveraging known malware tools such as SystemBC, China Chopper, and Pay2Key, to infiltrate networks and exfiltrate sensitive data.

Goals & Targeting

Fox Kitten’s targeting strategy focuses on sectors with critical infrastructure and sensitive data, such as oil and gas, defense, healthcare, and technology. The group likely aims to gather intelligence for strategic advantage, possibly in support of national interests or geopolitical objectives. Its global targeting suggests a focus on maximizing access to diverse industries and regions, potentially to build a repository of sensitive information.

Enhanced Description

Fox Kitten is a cyber threat actor with suspected ties to the Iranian government, first observed since at least 2017. The group has demonstrated significant operational persistence, targeting organizations across various industries—oil and gas, technology, government, defense, healthcare, manufacturing, and engineering—in regions including the Middle East, North Africa, Europe, Australia, and North America. Fox Kitten's activities suggest a high level of sophistication, utilizing a combination of malware tools such as SystemBC, China Chopper, and Pay2Key, along with advanced tactics to compromise victim networks. The group’s primary motivation appears to be cyber-espionage and data exfiltration, though specific strategic goals remain unclear in available intelligence. Fox Kitten's use of TTPs including remote services exploitation, credential dumping via LSASS memory, and persistence mechanisms highlights its ability to quietly infiltrate targets and maintain long-term access.

Key Capabilities

  • Advanced persistent threat (APT) tactics
  • Use of known malware tools (e.g., SystemBC, China Chopper)
  • Network infiltration and data exfiltration
  • Credential harvesting via LSASS memory dumping
  • Remote service exploitation
  • Persistence through web shells and backdoors

MITRE ATT&CK Tactics

Initial Access
Credential Access
Defense Evasion
Discovery
Lateral Movement
Exfiltration

ATT&CK Techniques

T1053.005: Scheduled Task
T1560.001: Archive via Utility
T1021.005: VNC
T1087.002: Domain Account
T1036.005: Match Legitimate Resource Name or Location
T1021.004: SSH
T1555.005: Password Managers
T1005: Data from Local System
T1190: Exploit Public-Facing Application
T1572: Protocol Tunneling
T1505.003: Web Shell
T1217: Browser Information Discovery
T1136.001: Local Account
T1003.001: LSASS Memory
T1036.004: Masquerade Task or Service
T1012: Query Registry
T1083: File and Directory Discovery
T1102: Web Service
T1059.001: PowerShell
T1059.003: Windows Command Shell

Software / Tooling

SystemBC
China Chopper
Pay2Key

Campaigns & Victims

Fox Kitten’s campaigns typically involve long-term infiltration and data exfiltration. The group has been linked to multiple attacks across sectors, with specific patterns including the use of web shells for persistence and credential dumping via LSASS memory. While no specific high-profile campaign names are publicly documented, Fox Kitten's operational tempo suggests a steady activity level targeting diverse industries globally.

IOC Patterns

  • Credential dumping via LSASS memory
  • Remote service exploitation (T1210)
  • Use of web shells for persistence
  • Exfiltration over legitimate channels
  • Scheduled task creation

Recommended Actions

  • Monitor network traffic for signs of remote service exploitation and web shell activity.
  • Implement strict controls on RDP access and disable unused RDP endpoints.
  • Correlate process monitoring data to detect LSASS memory dumping activities.
  • Regularly audit account permissions to identify unauthorized access points.
  • Use Honeypots to detect potential Fox Kitten TTPs.

Suggested Tags

APT
espionage
state-sponsored
cyber-espionage

Confidence Assessment

High confidence in Fox Kitten's existence and APT activities, particularly regarding its suspected Iranian government nexus. However, specific details about primary motivation, long-term goals beyond data collection, and exact toolset capabilities remain unclear. Additional intelligence on campaign specifics could enhance understanding of this group’s operational methods.

ATT&CK Techniques

Collection
5 techniques
Command & Control
4 techniques
Discovery
7 techniques
Lateral Movement
5 techniques
Stealth
5 techniques

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

Indicators of Compromise

No IOCs linked yet.

References

  1. CISA AA20-259A Iran-Based Actor September 2020 — CISA. (2020, September 15). Iran-Based Threat Actor Exploits VPN Vulnerabilities. Retrieved December 21, 2020.
  2. ClearSky Pay2Kitten December 2020 — ClearSky. (2020, December 17). Pay2Key Ransomware – A New Campaign by Fox Kitten. Retrieved December 21, 2020.
  3. ClearkSky Fox Kitten February 2020 — ClearSky. (2020, February 16). Fox Kitten – Widespread Iranian Espionage-Offensive Campaign. Retrieved December 21, 2020.
  4. Dragos PARISITE — Dragos. (n.d.). PARISITE. Retrieved December 21, 2020.
  5. Microsoft Threat Actor Naming July 2023 — Microsoft . (2023, July 12). How Microsoft names threat actors. Retrieved November 17, 2023.
  6. CrowdStrike PIONEER KITTEN August 2020 — Orleans, A. (2020, August 31). Who Is PIONEER KITTEN?. Retrieved December 21, 2020.

Intel Summary

41

Techniques

3

Tools

0

Campaigns

0

IOCs

0

Observed Data

11

Tactics

Tags

Healthcare Targeting
Critical Infrastructure
Government Targeting
APT
espionage
state-sponsored
cyber-espionage

Details

MITRE ID
G0117
Type
Unknown
Country of Origin
I
Confidence
90%
Added
May 2, 2026
STIX ID
intrusion-set--c21dd6f1-1364-4a70-a1f7-783080ec34ee
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.